Windows Token Privileges: A Field Checklist
Lab whoami /priv dump, OpenProcess notes on a process we own, integrity vs enabled privileges — no token-steal PoC.
Lab whoami /priv dump, OpenProcess notes on a process we own, integrity vs enabled privileges — no token-steal PoC.
Lab capsh –print and docker inspect seccomp/AppArmor, dropped caps, failed mount — no escape exploit.
Lab \du dump, a safe SECURITY DEFINER function, failed GRANT, search_path notes — no superuser exploit.
Lab klist encryption types, supported-etype table, GPO ‘Configure encryption types allowed for Kerberos’ — inventory, not cracking.
Lab klist dump, field-by-field decode of times and checksum types, clock-skew 401 — no ticket-forging steps.
Lab spooler service ACL and RPC interface dump, Point-and-Print registry, 7036/808 logs — no spool exploit.
Lab registry/GPO signing dumps, Wireshark NTLM field names, failed-auth 4625 — no relay tool command line that fires.
Lab event 4742/4768 samples redacted, computer-account naming checks, patch verification — no noPac exploit.